AWS Certified Data Engineer Associate DEA-C01 Practice Question
Your company stores sensitive PII in an Amazon Redshift RA3 cluster. Security mandates that all data at rest must be encrypted using keys that the security team can audit and rotate within AWS, without operating any hardware security modules. What is the MOST operationally efficient way to meet this requirement?
Configure the cluster to use server-side encryption with customer-provided keys (SSE-C) for its managed storage.
Encrypt data client-side before loading, then disable Amazon Redshift encryption to avoid double encryption.
Enable cluster encryption with an AWS KMS customer managed key when creating or modifying the cluster.
Create an AWS CloudHSM cluster and store the Redshift cluster key there.
Enabling cluster-level encryption with an AWS KMS customer managed key satisfies the requirement because Amazon Redshift RA3 clusters integrate directly with KMS. The security team can view CloudTrail records of each key use and enable automatic annual rotation or rotate the key on demand. Server-side encryption with customer-provided keys (SSE-C) does not apply to Redshift storage, client-side encryption plus disabling cluster encryption removes managed key auditing, and CloudHSM adds operational overhead and is not supported for RA3 node types.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an AWS KMS customer managed key?
Open an interactive chat with Bash
How does Amazon Redshift integrate with AWS KMS for encryption?
Open an interactive chat with Bash
Why is CloudHSM not recommended for RA3 nodes in this case?
Open an interactive chat with Bash
What is AWS KMS and how does it integrate with Amazon Redshift?
Open an interactive chat with Bash
What are RA3 node types in Amazon Redshift, and why is CloudHSM not compatible?
Open an interactive chat with Bash
Why is server-side encryption with customer-provided keys (SSE-C) not applicable for Redshift storage?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .